Hackers Exploit 32 Zero-Days on Day One of Pwn2Own Ireland
Tech

Hackers Exploit 32 Zero-Days on Day One of Pwn2Own Ireland

TechNews Editorial
TechNews EditorialOct 7, 2026 · 1 min read
Share

Why it matters

The event exposes critical zero-day vulnerabilities across major hardware and software, giving vendors 90 days to issue security patches before public disclosure.

The facts

  • Security researchers exploited 32 zero-days on the first day of Pwn2Own Ireland 2026.
  • Participants earned $388,500 after hacking devices like the Samsung Galaxy S26.
  • Vendors have 90 days to issue patches before the Zero Day Initiative publicly discloses the flaws.

Security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 on the first day of the Pwn2Own Ireland 2026 competition. They exploited 32 zero-days during the opening rounds.

Competitors target products across seven categories during the contest. These categories include mobile phones, printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and wellness healthcare devices.

Hackers target mobile and database tech

Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security successfully hacked the Samsung Galaxy S26 flagship. Some of the bugs used in each challenge were already known to the vendor.

Vũ Chí Thành and Huỳnh Đức Tin of VinSOC topped the leaderboard. They chained seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub and won $40,000. They also won an additional $40,000 for a five zero-day exploit chain targeting the Oracle Autonomous AI Database.

Two security researchers demonstrate control of a compromised smart lighting hub as connected lamps respond to their commands.
Illustration: AI & Tech News

Researchers hit AI and smart speakers

Security researchers also demonstrated LiteLLM zero-days and hacked Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers. They took down the OpenAI Codex cloud-based AI coding agent with a single argument-injection bug. They also exploited four vulnerabilities to compromise a Sonos Era 300 smart speaker.

Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club targeted the Google Pixel 10. However, they could not get their exploit to work within the allotted time.

Read nextSigil Wen Launches Underdog, a Private AI Assistant Competitor

The Zero Day Initiative organizes the hacking competition to identify zero-day vulnerabilities in targeted devices before threat actors exploit them. Vendors have 90 days to release security updates after flaws are exploited at Pwn2Own before Trend Micro's ZDI publicly discloses them.

Hackers will again target devices in the AI infrastructure, printers, smart home, and wellness categories, as well as the Samsung Galaxy S26 and the Google Pixel 10 on the second day of the contest. They will attempt to hack the Google Pixel 10 and Samsung Galaxy S26 flagships, along with multiple smart home, AI infrastructure, and printer devices, on the third day.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading